South Korea's president orders probe into AI-assisted bank cyberattacks

Fintech News

South Korea’s president orders probe into AI-assisted bank cyberattacks #

South Korean President Lee Jae Myung has ordered authorities to investigate a series of cyberattacks on the country’s financial sector after personal data belonging to tens of thousands of customers was exposed at several major banks over a matter of days.

Presidential spokesperson Kang Yu-jung confirmed on Sunday that the president had been briefed on the incidents and instructed officials to act “with a grave awareness of the seriousness of the matter.” The directive also called for concrete countermeasures to prevent further breaches.

The incidents came to light on Thursday when Shinhan Bank disclosed that roughly 25,000 customers had their personal information compromised, including names, phone numbers, annual income figures, loan limits, and in some cases resident registration numbers. The following day, KB Kookmin Bank, Hana Bank, and BNK Busan Bank each reported similar incidents. Hana Bank said personal data of 89 customers had been exposed.

The breaches extended beyond major commercial banks. Yegaram Savings Bank reported a leak affecting approximately 40,000 customers, while Hyundai Capital disclosed that data belonging to 146 housing loan agents had been accessed without authorization.

Investigators are examining whether artificial intelligence tools played a role in the attacks. South Korean media reports said traces of a Chinese-language AI penetration-testing tool were found on a server believed to have been used in the Shinhan Bank attack. The server’s metadata reportedly referenced a phrase consistent with an AI-powered autonomous penetration-testing system built on a large language model, pointing to a possible link to an open-source tool known as ARTEX AI. Authorities have not yet confirmed the identity or location of the attackers, though investigators suspect the hackers were operating from overseas.

Police launched a formal investigation and the Financial Services Commission convened an emergency meeting with chief executives from across the sector to discuss a response. FSC chairman Lee warned that the entire industry must “remain on the highest alert.” Regulators also urged firms to participate in government-led AI security testing initiatives and to accelerate adoption of AI-based defensive tools.

Authorities said they found no evidence that sensitive payment credentials had been leaked but warned of the potential for secondary harm, particularly through voice phishing attacks exploiting the stolen personal data.

Source: The Korea Times